Initial categorical analysis
Start with role, organization, size, and ePHI-scope categories against the current 45 CFR Part 164 Subpart C. The intake collects no PHI and is directional guidance, not a formal risk analysis.
Start a source-backed readiness intake for the current HIPAA Security Rule, covering 45 CFR §§164.302–164.318. Use categories only — never submit PHI.
A compact path from categorical analysis to prioritized findings and evidence-ready remediation guidance.
Start with role, organization, size, and ePHI-scope categories against the current 45 CFR Part 164 Subpart C. The intake collects no PHI and is directional guidance, not a formal risk analysis.
Review a directional nine-finding summary across administrative, physical, and technical safeguards, with Critical, High, and Medium priorities, 45 CFR citations, and practical remediation actions.
Map each gap to representative evidence artifacts and next-step guidance. The $199 HIPAA Evidence-Ready Readiness Pack provides the gated PDF deliverable—not a formal attestation or organization-specific audit.
Start with categorical scope guidance, then choose the paid educational deliverable when you want a structured, source-backed readiness pack.
The current intake is a directional first pass, not an organization-specific finding set.
A purchased, gated PDF that turns the public framework into a concise educational readiness deliverable.
Educational readiness guidance only — not legal advice, a formal attestation, or a substitute for an organization-specific assessment.
Continue to secure checkout — $199The first pass is intentionally limited to non-PHI categories that shape the readiness path.
Covered entity, business associate, clearinghouse, hybrid entity, or a healthcare service provider that is still mapping its HIPAA role.
Clinical systems, cloud and SaaS services, connected systems, limited environments, or business associate service scope.
Current requirements in 45 CFR §§164.302–164.318, with the HHS NPRM kept clearly separate as proposed and not final.
A public, directional summary of nine prioritized findings across administrative, physical, and technical safeguards. Use the remediation actions as a starting point, then validate scope and risk through a formal organization-specific analysis.
| # | Priority | Safeguard | Finding | 45 CFR provision | Remediation action | Primary source | Analyze |
|---|---|---|---|---|---|---|---|
| 1 | Critical | Administrative | No documented enterprise-wide risk analysis identifies ePHI threats, vulnerabilities, likelihood, and potential impact. | 45 CFR §164.308(a)(1)(ii)(A) | Inventory ePHI systems and flows, document threats and vulnerabilities, rate likelihood and impact, and retain the signed analysis. | eCFR §164.308(a)(1)(ii)(A) | Analyze my org → |
| 2 | High | Administrative | Risk analysis findings are not converted into a documented risk-management plan with assigned owners and due dates. | 45 CFR §164.308(a)(1)(ii)(B) | Prioritize treatment decisions from the risk analysis, assign accountable owners, set target dates, and track residual risk to closure. | eCFR §164.308(a)(1)(ii)(B) | Analyze my org → |
| 3 | High | Administrative | Security incident procedures do not clearly assign detection, response, reporting, and mitigation responsibilities. | 45 CFR §164.308(a)(6)(ii) | Document an incident workflow with escalation contacts, triage criteria, containment steps, reporting decisions, and post-incident mitigation. | eCFR §164.308(a)(6)(ii) | Analyze my org → |
| 4 | Critical | Physical | Facility access controls do not consistently limit and validate physical access to systems and facilities that house ePHI. | 45 CFR §164.310(a)(2)(iii) | Maintain a facility access procedure covering authorization, badge or key review, visitor handling, and periodic validation of physical access. | eCFR §164.310(a)(2)(iii) | Analyze my org → |
| 5 | Medium | Physical | Workstation-use requirements do not define permitted functions, physical surroundings, or safeguards for workstations accessing ePHI. | 45 CFR §164.310(b) | Publish workstation-use rules for approved functions, placement, privacy, locking, and prohibited handling, then train and attest workforce members. | eCFR §164.310(b) | Analyze my org → |
| 6 | High | Physical | Device and media procedures do not cover receipt, removal, disposal, reuse, or accountability for ePHI-containing media. | 45 CFR §164.310(d)(2)(i)–(iv) | Track media custody and movement, approve removals, sanitize or destroy media before disposal or reuse, and retain disposal or reuse records. | eCFR §164.310(d)(2)(i)–(iv) | Analyze my org → |
| 7 | Critical | Technical | Systems do not consistently enforce unique user access, emergency access, automatic logoff, and encryption or decryption controls. | 45 CFR §164.312(a)(1), (a)(2)(i)–(iv) | Define access roles, issue unique user IDs, document emergency access, configure automatic logoff where appropriate, and manage encryption or decryption controls. | eCFR §164.312(a)(1), (a)(2)(i)–(iv) | Analyze my org → |
| 8 | Medium | Technical | Electronic systems lack a reviewed audit trail that records and examines activity involving ePHI and system resources. | 45 CFR §164.312(b) | Enable audit logging for relevant systems, centralize or protect logs, define review cadence and escalation, and retain review evidence. | eCFR §164.312(b) | Analyze my org → |
| 9 | High | Technical | User authentication and transmission protections are not consistently verified for systems that access or send ePHI. | 45 CFR §164.312(d) and (e)(1) | Define authentication checks that verify identity and protect ePHI in transit with documented transmission-security controls and exception handling. | eCFR §§164.312(d), (e)(1) | Analyze my org → |
This representative checklist offers directional preparation guidance, not an organization-specific audit opinion. Use it to organize evidence for review against your own scope, policies, systems, and risk decisions.
| # | Artifact | Safeguard | 45 CFR provision | Preparation guidance | Official source |
|---|---|---|---|---|---|
| 1 | Documented enterprise-wide ePHI risk analysis | Administrative | 45 CFR §164.308(a)(1)(ii)(A) | Assemble the current system and data-flow inventory, threat and vulnerability analysis, likelihood and impact ratings, methodology, scope, approval date, and retained sign-off. | eCFR §164.308(a)(1)(ii)(A) |
| 2 | Risk-management plan and treatment tracker | Administrative | 45 CFR §164.308(a)(1)(ii)(B) | Assemble the approved plan tied to risk-analysis findings, with treatment decisions, accountable owners, target dates, residual-risk decisions, status history, and evidence of periodic review. | eCFR §164.308(a)(1)(ii)(B) |
| 3 | Security incident-response procedure and test record | Administrative | 45 CFR §164.308(a)(6)(ii) | Retain the approved response procedure plus a dated tabletop or other test record showing participants, detection and escalation steps, reporting decisions, lessons learned, and corrective actions. | eCFR §164.308(a)(6)(ii) |
| 4 | Facility-access authorization and review records | Physical | 45 CFR §164.310(a)(2)(iii) | Assemble the facility-access procedure, authorized-person or badge and key lists, visitor controls, review dates, approver sign-offs, and records showing access was removed or updated when roles changed. | eCFR §164.310(a)(2)(iii) |
| 5 | Workstation-use policy, training attestations, and inspection records | Physical | 45 CFR §164.310(b) | Retain the approved policy, dated workforce training and attestations, and representative inspection records covering permitted functions, workstation placement, privacy, locking, and prohibited handling. | eCFR §164.310(b) |
| 6 | Device and media inventory, movement, sanitization, and disposal records | Physical | 45 CFR §164.310(d)(2)(i)–(iv) | Assemble an inventory and custody trail for devices and media, removal approvals, movement logs, sanitization or destruction certificates, disposal records, and reuse decisions with dates and responsible personnel. | eCFR §164.310(d)(2)(i)–(iv) |
| 7 | Access-control and IAM configuration evidence | Technical | 45 CFR §164.312(a)(1), (a)(2)(i)–(iv) | Capture dated configuration exports or screenshots, role and unique-ID standards, emergency-access procedures, automatic-logoff settings, encryption or decryption controls, and review or approval records. | eCFR §164.312(a)(1), (a)(2)(i)–(iv) |
| 8 | Audit-log configuration and review records | Technical | 45 CFR §164.312(b) | Retain logging configurations for relevant systems, a protected or centralized log sample, dated review reports, reviewer approvals, escalation records, and the defined retention period. | eCFR §164.312(b) |
| 9 | Authentication and transmission-security validation record | Technical | 45 CFR §164.312(d), (e)(1) | Assemble dated validation or test results for identity verification and ePHI transmission protections, including protocols, scope, exceptions, remediation owners, approval, and retention of follow-up evidence. | eCFR §§164.312(d), (e)(1) |
Current rule: 45 CFR Part 164 Subpart C, §§164.302–164.318 — official eCFR text. The current Security Rule is the source-of-truth frame for this Slice 1 intake.
Proposed rule — not final: HHS HIPAA Security Rule NPRM. ComplianceStack labels this HHS notice as proposed and does not treat it as an enacted replacement for the current rule.
These examples show the shape of the paid readiness experience rather than organization-specific findings or delivered results.
Inventory ePHI systems and flows, document threats and vulnerabilities, rate likelihood and impact, and retain the signed analysis.
Assemble the current system and data-flow inventory, threat and vulnerability analysis, likelihood and impact ratings, methodology, scope, approval date, and retained sign-off.
Prioritize treatment decisions from the risk analysis, assign accountable owners, set target dates, and track residual risk to closure.
The Stripe-connected HIPAA Evidence-Ready Readiness Pack is the paid next step after the free intake. The public gaps summary and nine-row evidence checklist above remain representative and directional; verified purchasers receive a gated PDF export containing these nine prioritized gaps and nine evidence artifacts with their 45 CFR Part 164 citations. Organization-specific analysis and future deliverables may require additional review.
Stripe-secured checkout · Server-priced at $199 · No account required.
ComplianceStack’s free HIPAA readiness analysis is a categorical, directional first pass based on role, organization type, organization size, and ePHI-scope inputs. It does not collect PHI and does not replace an organization-specific risk analysis or formal audit.
ComplianceStack’s $199 HIPAA Evidence-Ready Readiness Pack contains a gated PDF for verified purchasers with nine prioritized gaps, remediation guidance, and nine representative evidence artifacts, each mapped to 45 CFR Part 164 citations and official eCFR sources.
ComplianceStack’s public nine-gap summary and nine-row evidence checklist are representative, directional readiness outputs with remediation guidance and 45 CFR citations from official eCFR sources. They are not organization-specific audit findings, a formal attestation, or a substitute for an organization-specific assessment.
ComplianceStack’s HIPAA Evidence-Ready Readiness Pack checkout is Stripe-secured and server-priced at $199, and no account is required. Starting checkout opens the secure payment flow for the paid pack.